PT-2020-16938 · Sourcecodester · Sourcecodester Water Billing System
Published
2020-11-17
·
Updated
2020-12-01
·
CVE-2020-28183
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SourceCodester Water Billing System version 1.0
Description
The issue is related to a SQL injection vulnerability. It affects the
username and password parameters in the "process.php" endpoint. This allows for potential SQL injection attacks.Recommendations
For SourceCodester Water Billing System version 1.0, consider restricting access to the "process.php" endpoint until a patch is available. As a temporary workaround, avoid using the
username and password parameters in this endpoint to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Water Billing System